skills/azure-attestation/SKILL.md
Expert knowledge for Azure Attestation development including troubleshooting, best practices, security, configuration, and deployment. Use when validating attestation tokens, authoring policies, enforcing SGX/TPM baselines, or configuring private endpoints, and other Azure Attestation related development tasks. Not for Azure Confidential Computing (use azure-confidential-computing), Azure Virtual Enclaves (use azure-virtual-enclaves), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Key Vault (use azure-key-vault).
npx skillsauth add microsoftdocs/agent-skills azure-attestationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This skill provides expert guidance for Azure Attestation. Covers troubleshooting, best practices, security, configuration, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.
IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g.,
L35-L120), useread_filewith the specified lines. For categories with file links (e.g.,[security.md](security.md)), useread_fileon the linked reference file
IMPORTANT for Agent: If
metadata.generated_atis more than 3 months old, suggest the user pull the latest version from the repository. Ifmcp_microsoftdocstools are not available, suggest the user install it: Installation Guide
This skill requires network access to fetch documentation content:
mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.| Category | Lines | Description | |----------|-------|-------------| | Troubleshooting | L33-L37 | Diagnosing and fixing common Azure Attestation failures, error codes, policy/quote validation issues, configuration mistakes, and connectivity or runtime problems. | | Best Practices | L38-L46 | Guidance on validating attestation tokens, writing secure attestation policies, and configuring/enforcing SGX and TPM attestation baselines using sample policies. | | Security | L47-L52 | Using Azure Policy with Attestation, enforcing compliance, and best practices to harden, secure, and protect Azure Attestation deployments and configurations. | | Configuration | L53-L69 | Configuring Azure Attestation policies (grammar, versions, claim rules), policy signer certs, and monitoring/logging via Azure Monitor, CLI, PowerShell, and log schema. | | Deployment | L70-L73 | How to create and configure a private endpoint for Azure Attestation using PowerShell, including network setup and secure access to attestation resources. |
| Topic | URL | |-------|-----| | Troubleshoot common Azure Attestation errors and issues | https://learn.microsoft.com/en-us/azure/attestation/troubleshoot-guide |
| Topic | URL | |-------|-----| | Interpret and validate Azure Attestation tokens with examples | https://learn.microsoft.com/en-us/azure/attestation/attestation-token-examples | | Author secure and correct Azure Attestation policies | https://learn.microsoft.com/en-us/azure/attestation/author-sign-policy | | Configure custom TCB baseline enforcement for SGX attestation | https://learn.microsoft.com/en-us/azure/attestation/custom-tcb-baseline-enforcement | | Use sample SGX attestation policies in Azure | https://learn.microsoft.com/en-us/azure/attestation/policy-examples | | Use sample TPM attestation policies in Azure | https://learn.microsoft.com/en-us/azure/attestation/tpm-attestation-sample-policies |
| Topic | URL | |-------|-----| | Apply built-in Azure Policy definitions for Attestation | https://learn.microsoft.com/en-us/azure/attestation/policy-reference | | Harden and secure Azure Attestation deployments | https://learn.microsoft.com/en-us/azure/attestation/secure-attestation |
| Topic | URL | |-------|-----| | Use Azure Attestation claim rule functions and operators | https://learn.microsoft.com/en-us/azure/attestation/claim-rule-functions | | Use Azure Attestation claim rule grammar in policies | https://learn.microsoft.com/en-us/azure/attestation/claim-rule-grammar | | Understand Azure Attestation claim sets and categories | https://learn.microsoft.com/en-us/azure/attestation/claim-sets | | Enable diagnostic logging for Azure Attestation | https://learn.microsoft.com/en-us/azure/attestation/enable-logging | | Reference for Azure Attestation monitoring and log schema | https://learn.microsoft.com/en-us/azure/attestation/logs-data-reference | | Monitor Azure Attestation with Azure Monitor | https://learn.microsoft.com/en-us/azure/attestation/monitor-logs | | Configure Azure Attestation policy signer certificates | https://learn.microsoft.com/en-us/azure/attestation/policy-signer-examples | | Configure Azure Attestation policy language version 1.0 | https://learn.microsoft.com/en-us/azure/attestation/policy-version-1-0 | | Configure Azure Attestation policy language version 1.1 | https://learn.microsoft.com/en-us/azure/attestation/policy-version-1-1 | | Configure Azure Attestation policy language version 1.2 | https://learn.microsoft.com/en-us/azure/attestation/policy-version-1-2 | | Set up Azure Attestation using Azure CLI | https://learn.microsoft.com/en-us/azure/attestation/quickstart-azure-cli | | Configure Azure Attestation provider with PowerShell | https://learn.microsoft.com/en-us/azure/attestation/quickstart-powershell | | Understand and use Azure Attestation log data | https://learn.microsoft.com/en-us/azure/attestation/view-logs |
| Topic | URL | |-------|-----| | Create Azure Attestation private endpoint with PowerShell | https://learn.microsoft.com/en-us/azure/attestation/private-endpoint-powershell |
tools
Expert knowledge for Microsoft Foundry (aka Azure AI Foundry) development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building Foundry agents with IQ retrieval, Entra RBAC, Azure OpenAI, M365/Teams publishing, or MCP tools, and other Microsoft Foundry related development tasks. Not for Microsoft Foundry Classic (use microsoft-foundry-classic), Microsoft Foundry Local (use microsoft-foundry-local), Microsoft Foundry Tools (use microsoft-foundry-tools).
tools
Expert knowledge for Microsoft Foundry Local (aka Azure AI Foundry Local) development including best practices, configuration, and integrations & coding patterns. Use when compiling HF models with Olive, managing local models via CLI, or building chat, embeddings, or transcription apps, and other Microsoft Foundry Local related development tasks. Not for Microsoft Foundry (use microsoft-foundry), Microsoft Foundry Classic (use microsoft-foundry-classic), Microsoft Foundry Tools (use microsoft-foundry-tools), Azure Local (use azure-local).
tools
Expert knowledge for Microsoft Foundry Classic (aka Azure AI Foundry classic) development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when configuring Foundry agents, routing Azure OpenAI models, integrating tools/RAG, securing endpoints, or deploying hubs, and other Microsoft Foundry Classic related development tasks. Not for Microsoft Foundry (use microsoft-foundry), Microsoft Foundry Local (use microsoft-foundry-local), Microsoft Foundry Tools (use microsoft-foundry-tools).
development
Expert knowledge for Azure Web PubSub development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when using WebSockets/MQTT, Socket.IO, Functions bindings, geo-replication, or Premium autoscale in Web PubSub, and other Azure Web PubSub related development tasks. Not for Azure SignalR Service (use azure-signalr-service), Azure Event Hubs (use azure-event-hubs), Azure Service Bus (use azure-service-bus), Azure Relay (use azure-relay).